Show filters
58 Total Results
Displaying 11-20 of 58
Sort by:
Attacker Value
Unknown
CVE-2016-0306
Disclosure Date: May 17, 2016 (last updated November 25, 2024)
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.41, 8.0 before 8.0.0.13, and 8.5 before 8.5.5.10, when FIPS 140-2 is enabled, misconfigures TLS, which allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors.
0
Attacker Value
Unknown
CVE-2016-0283
Disclosure Date: March 19, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the OpenID Connect (OIDC) client web application in IBM WebSphere Application Server (WAS) Liberty Profile 8.5.5 before 8.5.5.9 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
0
Attacker Value
Unknown
CVE-2015-7417
Disclosure Date: January 23, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server 7.0 before 7.0.0.41, 8.0 before 8.0.0.12, and 8.5 before 8.5.5.9 allows remote authenticated users to inject arbitrary web script or HTML via crafted data from an OAuth provider.
0
Attacker Value
Unknown
CVE-2015-5004
Disclosure Date: December 15, 2015 (last updated October 05, 2023)
The Edge Component Caching Proxy in IBM WebSphere Application Server (WAS) 8.0 before 8.0.0.12 and 8.5 before 8.5.5.8 does not properly encrypt data, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-2017
Disclosure Date: November 08, 2015 (last updated October 05, 2023)
CRLF injection vulnerability in IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 before 8.0.0.12, and 8.5 before 8.5.5.8 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.
0
Attacker Value
Unknown
CVE-2015-4938
Disclosure Date: August 22, 2015 (last updated October 05, 2023)
IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5.7 allows remote attackers to spoof servlets and obtain sensitive information via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-1932
Disclosure Date: August 22, 2015 (last updated October 05, 2023)
IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5.7 and WebSphere Virtual Enterprise before 7.0.0.7 allow remote attackers to obtain potentially sensitive information about the proxy-server software by reading the HTTP Via header.
0
Attacker Value
Unknown
CVE-2015-1946
Disclosure Date: July 14, 2015 (last updated October 05, 2023)
IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.6, and WebSphere Virtual Enterprise 7.0 before 7.0.0.6 for WebSphere Application Server (WAS) 7.0 and 8.0, does not properly implement user roles, which allows local users to gain privileges via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-1936
Disclosure Date: July 14, 2015 (last updated October 05, 2023)
The administrative console in IBM WebSphere Application Server (WAS) 8.0.0 before 8.0.0.11 and 8.5 before 8.5.5.6, when the Security feature is disabled, allows remote authenticated users to hijack sessions via the JSESSIONID parameter.
0
Attacker Value
Unknown
CVE-2015-1927
Disclosure Date: July 14, 2015 (last updated October 05, 2023)
The default configuration of IBM WebSphere Application Server (WAS) 7.0.0 before 7.0.0.39, 8.0.0 before 8.0.0.11, and 8.5 before 8.5.5.6 has a false value for the com.ibm.ws.webcontainer.disallowServeServletsByClassname WebContainer property, which allows remote attackers to obtain privileged access via unspecified vectors.
0